Skip to main content
IlmFlow, madrasa management software
Admin & compliance

GDPR for madrasahs: a plain-English guide

By Uthmaan Sadik · Updated 8 August 2026 · 6 min read

Data protection sounds like something only big organisations worry about. It is not. The moment you write down a child's name and their parent's phone number, UK GDPR applies to your madrasah. The good news is that the law mostly asks for things any careful madrasah would want to do anyway. Here is what it means in practice. This is general guidance, not legal advice.

You hold more sensitive data than you think

A typical madrasah holds names, addresses, dates of birth, parent contact details, attendance, exam results, medical or dietary notes, and safeguarding records. Some of this, particularly health and safeguarding information, is treated as especially sensitive.

Recognising that you are a data controller is the first step. It simply means you are responsible for looking after this information properly.

Know why you hold each piece of data

The core idea of GDPR is that you should only collect data you actually need, use it only for the reason you collected it, and not keep it forever. In practice, that means you can hold a child's emergency contact because you need it to keep them safe, but you should not be collecting information that serves no purpose.

A short, honest note to parents at enrolment explaining what you collect and why (often called a privacy notice) covers most of this obligation.

Keep it secure

Security is where most small organisations slip. The register in a notebook that travels home, the spreadsheet emailed between teachers, the WhatsApp group with every parent's number visible to all: these are the everyday risks.

  • Limit who can see what: a teacher needs their own class, not the whole madrasah
  • Protect access with proper logins, not a shared password on a sticky note
  • Avoid personal data drifting into personal phones, notebooks and inboxes
  • Keep it in one controlled place rather than scattered across many

Respect parents' rights

Parents (and children, depending on age) have rights over their data. The two you are most likely to meet are the right to see the information you hold about their child, and the right to have it corrected if it is wrong.

You do not need a legal team for this. You need to know where a child's information lives so that, if a parent asks, you can find it and share it without a week of digging through notebooks.

Do not keep records forever

When a child leaves, you should not hold their full records indefinitely. Decide on a sensible retention period, keep what you genuinely need (safeguarding records often need to be kept longer), and securely dispose of the rest.

Being able to export or remove a former student's data cleanly is part of this, and worth checking your system can actually do.

Have a plan if something goes wrong

A data breach is not only a hacker. It is a lost notebook, a spreadsheet sent to the wrong parent, or a phone left on a bus. If something like that happens and it puts people at risk, you may be required to report it, sometimes within 72 hours.

You do not need to be an expert. You need to know who in your madrasah is responsible, and to take it seriously when it happens.

What to look for in your software

The right system makes most of this straightforward rather than adding to your workload.

  • Role-based access, so people see only what they need
  • Proper individual logins, ideally with an extra security step for admins
  • Your data kept private to your madrasah and not shared with other schools
  • The ability to export or remove a person's data on request
  • Payments that go to your own bank, so you are not passing card details around

Where to check the official guidance

This guide is deliberately plain-English and not exhaustive. For the primary source, the Information Commissioner's Office (the UK regulator) and GOV.UK both publish guidance written for organisations without a legal team.

Common questions

Does GDPR apply to a small madrasah?

Yes. The moment you write down a child's name and a parent's phone number, UK GDPR applies, whatever your size. It makes your madrasah a data controller, which simply means you are responsible for looking after that information properly.

What counts as sensitive data in a madrasah?

Names, addresses, dates of birth, parent contact details, attendance and exam results are all personal data. Medical or dietary notes and safeguarding records are treated as especially sensitive and need tighter handling and narrower access.

Is a WhatsApp group with all the parents a data protection risk?

It can be. Every parent's phone number is visible to everyone else in the group, which is a disclosure you may not have permission to make, and it is easy to send the wrong message to the wrong audience. A private portal per family avoids both problems.

How long should a madrasah keep student records?

There is no single answer, so decide on a sensible retention period and apply it consistently. Keep what you genuinely need, bear in mind safeguarding records often have to be kept longer, and securely dispose of the rest once a child has left.

What should you do if data is lost or sent to the wrong person?

Treat it seriously. A breach includes a lost notebook or a spreadsheet emailed to the wrong parent, not just hacking. If it puts people at risk you may be required to report it, in some cases within 72 hours, so know who in your madrasah is responsible before it happens.

How IlmFlow helps

IlmFlow is built to be GDPR-friendly: role-based access, individual logins with optional two-step verification, each madrasah's data kept private, and clean data export on request.

Start free trialBook a demo

More guides

Running your madrasah
How to run a madrasah attendance register that actually works
Hifz & Quran
Hifz tracking made simple: Sabak, Sabak Para and Dhor explained
Starting out
How to start a madrasah in the UK: a practical checklist